CVE-2025-2172: Aviatrix Controller

Medium severity, CVSS 6.6. EPSS: 12.2% chance of exploitation in the next 30 days.

Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 fail to sanitize user input prior to passing the input to command line utilities, allowing command injection via special characters in filenames

Affected products

Published 2025-06-23. Last modified 2026-06-17.